Android Device Admin Abuse Chained to Destructive Anti-Uninstall Commands

Detects Android applications that request Device Admin privileges followed by the execution of coercive commands, such as disabling biometric authentication, setting admin passwords, or enabling uninstall protection. This behavior is indicative of malicious applications (e.g., RatHat) aiming to establish persistence and prevent uninstallation by the user or security software.